CVE Watchtower

← Back to CVE List

CVE-2026-92230NVD

Description

Apache Karaf's XmlUtils cached XML parser/transformer factories in static ThreadLocal fields on long-lived container threads. Because a ThreadLocal value outlives the OSGi bundle that created it, repeated bundle or feature install, update, or refresh operations can leave successive bundle ClassLoader's pinned in memory and unreachable for garbage collection, leading to unbounded Metaspace growth and eventual denial of service of the Karaf instance.
Severity Level
UNKNOWN
Published Date
17/09/2026
Last Modified
18/09/2026
Exploitation Status
????
EPSS Score
0.40% (percentile 33.7%)

Weaknesses (CWE)

CWE-401 - CWE-401 Missing release of memory after effective lifetimeCWE-772 - CWE-772 Missing release of resource after effective lifetime

Affected & Patched Versions

ProductAffected VersionsPatched Version
Apache Software Foundation Apache Karaf0 - < 4.4.11N/A
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.
📧Email Delivery — Threat intel straight to your inbox.
♾️Unlimited Vendors — Track your entire stack.
🚨All New CVEs — Be the first to know.
⚙️Custom EPSS — Filter noise, focus on risk.
💬Webhooks — Slack & Teams integration.
🚫Ad-Free — Uninterrupted experience.